Antivirus warnings are false positives
WordShield contains no trojan, no virus, and no upload of any kind. The warning comes from heuristic rules, not from anything harmful in the program. This page explains why — and gives you three checks you can run yourself.
Why it gets flagged
1. No code-signing certificate
A code-signing certificate costs roughly ¥2000–4000 per year. A signed binary proves who authored it and that it hasn't been tampered with. An unsigned binary triggers Windows SmartScreen and most antivirus high-risk prompts by default. This is the single biggest cause — and it says nothing about whether the code is clean.
2. Reading input controls
WordShield works by reading the text of the focused input control. That is
technically the same family of behaviour as keylogging tools, so heuristic engines
err on the side of caution.
But WordShield excludes 74 apps by default — WeChat is first on that list
and is never captured — and password fields are detected and skipped entirely.
3. PyInstaller packaging
WordShield is packaged with PyInstaller into a single directory — which happens to be a packaging style malware also favours, adding to the suspicion score. Every legitimate Python-packaged desktop app hits this same wall.
Why we can say this plainly
WordShield makes zero network calls. There is no upload, no telemetry, no phone-home code anywhere in it — and you can verify that yourself with the offline test below.
Three checks you can run yourself
Don't take our word for it — take your own machine's.
Check 1 · Verify the file (SHA-256)
After downloading, run this in PowerShell (adjust the path to where you saved it):
Get-FileHash .\WordShield_v1.13.9.zip -Algorithm SHA256
If the output matches the string below, your file is
byte-for-byte identical to what we published — nothing was swapped or
injected in transit:
7008ac429af041f78413514a588371ea73707b68c61c08f430e0d36c0177e25e
Check 2 · Offline self-test
Disconnect from the network (unplug the cable or turn off Wi-Fi) and use WordShield normally: capture, search, organise — everything works. Software that actually wants to exfiltrate data dies the moment you go offline. WordShield is completely unaffected.
Check 3 · Look at what it stores
Data lives in %APPDATA%\WordShield\data\prompts.db. You can move that
location in settings, or just open the SQLite file and look inside —
it contains nothing but your own prompts.
Whitelist status by vendor
We are pursuing developer-level certification, not one-off per-file appeals.
| Vendor | Mechanism | Status |
|---|---|---|
| 360 Total Security | Software certification / developer whitelist (covers future versions) | In progress |
| VirusTotal | Multi-engine scan report (third-party corroboration) | In progress |
| Microsoft Defender | False-positive sample submission | Pending |
| Tencent PC Manager / Huorong | False-positive appeal | Pending |
Note: most "false positive appeal" flows whitelist a single file hash, which means re-appealing for every release. That's why we prioritise developer-level certification, which covers subsequent versions.
Still not comfortable?
- Run it first in Windows Sandbox or a VM and confirm the behaviour matches what we describe.
- Stay on the free tier (100 entries visible) until you're satisfied.
- Full refund within 10 days of purchase, no questions asked.
- Open
%APPDATA%\WordShield\data\prompts.dband look — it only holds your own text.